kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1beta1
metadata:
  name: {{ provisioner_name }}
subjects:
  - kind: ServiceAccount
    name: {{ serviceaccount }}
     # replace with namespace where provisioner is deployed
    namespace: {{ namespace }}
roleRef:
  kind: ClusterRole
  name: {{ provisioner_name }}
  apiGroup: rbac.authorization.k8s.io
